Real-world two-photon interference and proof-of-principle quantum key distribution 

immune to detector attacks 
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Several vulnerabilities of single photon detectors have recently been exploited to compromise the 
security of quantum key distribution (QKD) systems. In this letter we report the first proof-of- 
principle implementation of a new quantum key distribution protocol that is immune to any such 
attack. More precisely, we demonstrated this new approach to QKD in the laboratory over more 
than 80 km of spooled fiber, as well as across different locations within the city of Calgary. The 
robustness of our fibre-based implementation, together with the enhanced level of security offered 
by the protocol, confirms QKD as a realistic technology for safeguarding secrets in transmission. 
Furthermore, our demonstration establishes the feasibility of controlled two-photon interference in 
a real-world environment, and thereby removes a remaining obstacle to realizing future applications 
of quantum communication, such as quantum repeaters and, more generally, quantum networks. 



Quantum key distribution (QKD) promises the distri- 
bution of cryptographic keys whose secrecy is guaranteed 
by fundamental laws of quantum physics [TJ |2]- Start- 
ing with its invention in 1984[3], theoretical and experi- 
mental QKD have progressed rapidly. Information theo- 
retic security, which ensures that secret keys can be dis- 
tributed even if the eavesdropper. Eve, is only bounded 
by the laws of quantum physics, has been proven un- 
der various assumptions about the devices of the legit- 
imate QKD users, Alice and Bob[ll H]- Furthermore, 
experimental demonstrations employing quantum states 
of light have meanwhile resulted in key distribution over 
more than 100 km distance through optical fiber[6] or 
air|7i, QKD networks employing trusted nodes [5], as well 
as in commercially available products [S|. 

However, it became rapidly clear that some of the as- 
sumptions made in QKD proofs were difficult to meet 
in real implementations, which opened side channels 
for eavesdropping attacks. The most prominent exam- 
ples are the use of quantum states encoded into attenu- 
ated laser pulses as opposed to single photons[TU], and, 
more recently, various possibilities for an eavesdropper 
to remote-control or monitor single photon detectors |1 II- 
[H]. Fortunately, both side channels can be removed us- 
ing appropriately modified protocols. In the first case, 
randomly choosing between so-called signal or decoy 
states (quantum states encoded into attenuated laser 
pulses with different mean photon numbers) allows one 
to establish a secret key strictly from information con- 
veyed by single photons emitted by the lascr[15 17 . (We 
remind the reader that an attenuated laser pulse com- 
prising on average fi photons contains exactly one pho- 
ton with probability Pi{fi) — fj-e~^ |10j.) Furthermore, 
the recently proposed measurement-device independent 
(MDI) QKD protocol [IH] (for closely related work see 
[19j ) additionally ensures that controlling or monitoring 
detectors, regardless by what means, does not help the 
eavesdropper to gain information about the distributed 



key. Note that, while the two most prominent side chan- 
nels are removed by MDI-QKD, others remain open and 
have to be closed by means of appropriate experimental 
design (see the Supplemental Material). 

The MDI-QKD protocol is a clever time-reversed ver- 
sion of QKD based on the distribution and measurement 
of pairs of maximally entangled photons [20] : In the ideal- 
ized version, Alice and Bob randomly and independently 
prepare single photons in one out of the four qubit states 
\^)a,b e m, |1), I+), I-)], where |±) = 2-V2(|o) ± |1)). 
The photons are then sent to Charlie, who performs 
a Bell state measurement, i.e. projects the photons' 
joint state onto a maximally entangled Bell state|21j. 
Charlie then publicly announces the instances in which 
his measurement resulted in a projection onto IV" ) = 
2~^/^(|0)a«)|1)b-|1)a® |0)s) and, for these cases, Al- 
ice and Bob publicly disclose the bases (z, spanned by |0) 
and |1), or x, spanned by |±)) used to prepare their pho- 
tons. (They keep their choices of states secret.) Identify- 
ing quantum states with classical bits (e.g. |0), |— ) = 0, 
and |1), |-f) = 1) and keeping only events in which Char- 
lie found \ip~) and they picked the same basis, Alice and 
Bob now establish anti-correlated key strings. (Note that 
a projection of two photons onto \'ip~) indicates that the 
two photons, if prepared in the same basis, must have 
been in orthogonal states.) Bob then flips all his bits, 
thereby converting the anti-correlated strings into corre- 
lated ones. Next, the so-called x-key is formed out of 
all key bits for which Alice and Bob prepared their pho- 
tons in the x-basis; its error rate is used to bound the 
information an eavesdropper may have acquired during 
photon transmission. Furthermore, Alice and Bob form 
the z-key out of those bits for which both picked the z- 
basis. Finally, they perform error correction and privacy 
amplification [TJ [2] to the z-key, which results in the secret 
key. 

As in the entanglement-based protocol, the time- 
reversed version ensures that Eve cannot gain informa- 



tion by eavesdropping photons during transmission or by 
modifying the device that generates entanglement - ei- 
ther the source of photon pairs or the projective two- 
photon measurement, respectively - without leaving a 
trace [551 US]- Furthermore, the outstanding attribute 
of the MDI-QKD protocol is that it de-correlates detec- 
tion events (here indicating a successful projection onto 
the !'(/'") Bell state) from the values of the x- and z-key 
bits and hence the secret key bits. In other words, all 
side channels related to the detection setup, regardless 
whether actively attacked or passively monitored, do not 
help Eve gain information about the secret key. 

Unfortunately, the described procedure is currently dif- 
ficult to implement for two reasons, first of which is the 
lack of practical single photon sources. However, it is 
possible to replace the true single photons by attenuated 
laser pulses of varying mean photon number (i.e. signal 
and decoy states, as introduced above), and to establish 
the secret key using information only from joint measure- 
ments at Charlie's that stem from Alice and Bob both 
sending single photons [Mj- This procedure results in the 
same security against eavesdropping as the conceptually 
simpler one discussed above. The secret key rate, 5, dis- 
tilled from signal states, is then given by [18]: 
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where h2{X) denotes the binary entropy function eval- 
uated on X, and / describes the efficiency of error cor- 
rection with respect to Shannon's noisy coding theorem. 
Furthermore, Qfi, ef^, Qf^^, and e^^ are gains {Q - the 
probability of a projection onto \ip~) per emitted pair of 
pulses) and error rates (e - the ratio of erroneous to total 
projections onto |V'~)) in either the x- or z-basis for Al- 
ice and Bob sending single photons (denoted by subscript 
"11"), or for pulses emitted by Alice and Bob with mean 
photon number fj, and a (denoted by subscript "/icr" ) , re- 
spectively. While the latter are directly accessible from 
experimental data, the former have to be calculated us- 
ing a decoy state method [THl [21] (see the Supplemental 
Material). 

Second, a crucial element for MDI-QKD as well as 
future quantum repeaters and networks is a Bell state 
measurement (BSM)[3S]. However, this two-photon in- 
terference measurement has not yet been demonstrated 
with photons that were generated by independent sources 
and have travelled through separate deployed fibers (i.e. 
fibers that feature independent changes of propagation 
times and polarization transformations). To implement 
the BSM one requires that these photons be indistin- 
guishable, i.e. arrive simultaneously within their respec- 
tive coherence times, with equal polarization, and fea- 
ture sufficient spectral overlap. Yet, due to time-varying 
properties of optical fibers in a real- world environment, 
significant changes to photons' indistinguishability can 
happen in less than a minute, as depicted in Fig. [Tl Fur- 
thermore, the carrier frequencies of the signals generated 
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FIG. 1. (a) Drift of differential arrival time. Variation of ar- 
rival time difference of attenuated laser pulses emitted at Al- 
ice's and Bob's after propagation to Charlie, (b) Variation in 
the overlap of the polarization states of originally horizontally 
polarized light (emitted by Alice and Bob) after propagation 
to Charlie. Both panels include temperature data (crosses), 
showing correlation between variations of indistinguishability 
and temperature. In addition, despite local frequency locks, 
the difference between the frequencies of Alice's and Bob's 
lasers varied by up to 20 MHz per hour (not shown). 



at Alice's and Bob's generally vary. These instabilities 
make real-world Bell state measurements without stabi- 
lization by means of active feedback impossible. 

Hence, to enable MDI-QKD and pave the way for 
quantum repeaters and quantum networks, we developed 
the ability to track and stabilize photon arrival times and 
polarization transformations as well as the frequency dif- 
ference between Alice's and Bob's lasers during all mea- 
surements (for more information see the Supplemental 
Material). In order to ensure the indistinguishability of 
photons arriving at Charlie's and to allow, for the first 
time, Bell state measurements in a real-world environ- 
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TABLE I. Length and loss {£a, I a, £b, Ib) of the individual 
fiber links used to connect Alice and Charlie, and Charlie and 
Bob, respectively, for all tested setups. The table also lists the 
total length £ and total loss I = Ia + Ib (in dB). The last line 
details measurements outside the laboratory with deployed 
fiber. 



merit, we developed and implemented three stabilization 
systems (see Fig. [2]) : fully-automatic polarization stabi- 
lization, manual adjustment of photon arrival time, and 
manual adjustment of laser frequency. Note that au- 
tomating the frequency and timing stabilization systems 
is straightforward, particularly if the active control ele- 
ments are placed in Charlie's setup. 

We verified that we could indeed maintain the in- 
distinguishability of the photons by frequently measur- 
ing the visibility, Vhom, of the so-called Hong-Ou- 
Mandel dip [26] (a two-photon interference experiment 
that is closely related to a BSM). On average we found 
yffOj\/=47±l%, which is close to the maximum value of 
50% for attenuated laser pulses with a Poissonian pho- 
ton number distribution |27j . and thereby confirm that 
real-world two-photon interference is possible. 

To assess the feasibility of MDI-QKD, we implemented 
a proof-of-principle demonstration of MDI-QKD using 
the decoy state protocol proposed by Wang [24] . This pro- 
tocol requires that Alice and Bob choose between three 
different mean photon numbers: two non-zero values re- 
ferred to as signal and decoy as well as vacuum. We 
performed our experiments over four different distances 
(henceforth referred to as setups) comprising two differ- 
ent arrangements (see Fig.l2|: (i) Alice, Bob and Charlie 
are located within the same lab, and Alice and Bob are 
connected to Charlie via separate spooled fibers of var- 
ious lengths and loss, (ii) Alice, Bob and Charlie are 
located in different locations within the city of Calgary, 
and Alice and Bob are connected to Charlie by deployed 
fibers of 12.4 and 6.2 km length, respectively. The fiber 
lengths and loss in each setup are listed in Table 1. 

For each setup, we prepared all 4 combinations of 
Alice and Bob picking a state from the z-basis (i.e. 
|'0)a,s S [|0),|1)], where |0) and |1) denote time-bin 
qubits[5T] prepared in an early or late temporal mode), 
and all 4 combinations of picking a state from the x-basis 
(i.e. IV') A, B & [|+), |— )])• Using a detailed model of our 
MDI-QKD system |5Sj, we calculated the signal and decoy 
intensities that maximize the secret key rate produced by 
the decoy-state method for each setup. For our decoy in- 
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FIG. 2. Aerial view showing Alice (located at SAIT Poly- 
technic), Bob (located at the University of Calgary (U of 
C) Foothills campus) and Charlie (located at the U of C 
main campus). Also shown is the schematic of the experi- 
mental setup. Optically synchronized using a master clock 
(MC) at Charlie's, Alice and Bob (not shown; setup iden- 
tical to Alice's) generated time-bin qubits at 2 MHz rate 
encoded into Fourier-limited attenuated laser pulses using 
highly stable continuous- wave lasers at 1552.910 nm wave- 
length, temperature-stabilized intensity and phase modula- 
tors (IM, PM), and variable attenuators (ATT). The two 
temporal modes defining each time-bin qubit were of 500 ps 
(FWHM) duration and were separated by 1.4 ns. The qubits 
travelled through 12.4 and 6.2 km of deployed optical fibers 
to Charlie, where a 50/50 beam splitter followed by two gated 
(10 fj,s deadtime) InGaAs single photon detectors (SPD) al- 
lowed projecting the bi-partite state onto the [■(/'") Bell state. 
(This projection occurred if the two detectors indicate detec- 
tions with 1.4±0.4 ns time difference.) The MC, polarization 
controller (POC) and Alice's frequency shifter (FS) are used 
to maintain indistinguishability of the photons upon arrival 
at Charlie. These three feedback systems are detailed in the 
Supplemental Material. The individual setups for measure- 
ments using spooled fiber (arrangement (i)) are identical. 



tensity we generated attenuated laser pulses containing 
on average ji = a = 0.05 ± 5% photons and for our signal 
intensities we used a mean photon number between 0.25 
and 0.5 (the optimal value depends on loss). For each of 
the four distance configurations listed in Table 1, and for 
each of the 16 pairs of qubit states, we performed mea- 



surements of all 9 combinations of Alice and Bob using 
the signal, decoy or vacuum intensity. We recorded the 
number of joint detections in which one detector indi- 
cated an early arriving photon (or an early noise count), 
and the other detector indicated a late arriving photon 
(or a late noise count), which, for time-bin qubits, is re- 
garded as a projection onto the |i/'~)-state[5T]. Depend- 
ing on the observed detection rates, measurements took 
between 2 and 35 minutes. This data yields the gains, 
Q^^ and Q^„, and error rates, e^^ and e"^^, a subset of 
which is plotted in Fig. |3^. A complete list of gains and 
error rates is presented in the Supplemental Material. 



We then computed secret key rates according to Ec^. [T] 
after extracting Qf^ and ef^ using Wang's decoy state 
calculation 24] and assuming an error correction effi- 
ciency /=1.14[8^. As shown in Fig. [sb, all our measure- 
ments, both outside and inside the laboratory, and using 
up to 80 km of spooled fiber between Alice and Bob, 
output a positive secret key rate. Furthermore, using 
our model[25], we estimate that our setup allows secret 
key distribution up to a total loss of 18±4.8 dB, which is 
in agreement with our QKD results. Assuming the stan- 
dard loss coefficient for telecommunication fibers without 
splices of 0.2 dB/km, this value corresponds to a maxi- 
mum distance between Alice and Bob of 90±24 km. Note 
that moving from our proof-of-principle demonstration to 
the actual distribution of secret keys requires additional 
developments, which are detailed in the Supplemental 
Material. 



In summary, we have demonstrated that real-world 
quantum key distribution with practical attenuated laser 
pulses and immunity to detector hacking attacks is pos- 
sible using current technology. Our setup contains only 
standard, off-the-shelf components, its development into 
a complete QKD system follows well-known steps |S], and 
the extension to higher key rates using state-of-the-art 
detectors[5ni ED] is straightforward. We also point out 
that MDI-QKD is well suited for key distribution over 
long distances, and we expect that further developments 
will rapidly push the separation between Alice and Bob 
beyond its current maximum of 250 km!^. Finally, we 
remind the reader that the demonstrated possibility for 
Bell state measurements in a real-world environment and 
with truly independent photons also removes a remaining 
obstacle to building a quantum repeater, which promises 
quantum communication such as QKD over arbitrary dis- 
tances. 
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FIG. 3. (a) Measured error rates ef^^r and e^o- for Alice and 
Bob either both using signal intensity or both using decoy 
intensity as a function of total loss, I = Ia + Ib (in dB). We 
note that every other combination of intensities used in the 
decoy-state analysis requires Alice or Bob (or both) sending 
vacuum, and thus the error rate is 50% and not plotted, (b) 
Experimentally obtained and simulated secret key rates as a 
function of total loss, I — Ia + Ib (in dB), with I a — Ib, for 
optimized mean photon numbers. Experimental secret key 
rates are directly calculated from measured gains and error 
rates using the decoy state method ^24^ (see Supplemental Ma- 
terial for details). In both panels, the secondary x-axis shows 
distance assuming loss of 0.2 dB/km. Diamonds depict re- 
sults obtained using deployed fibers (see Fig. pk); all other 
data was obtained using fiber on spools. Uncertainties (one 
standard deviation) were calculated for all measured points 
assuming Poissonian detection statistics. We stress that the 
simulated values, computed using our model [28]. do not stem 
from fits but are based on parameters that have been estab- 
lished through independent measurements. Monte-Carlo sim- 
ulations using uncertainties in these measurements lead to 
predicted bands as opposed to lines (for more details see the 
Supplemental Material) . 
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SUPPLEMENTAL MATERIAL 
ENSURING INDISTINGUISHABILITY 

In order to ensure the indistinguishability of photons arriving at Charlie's and to allow Bell state measurements in 
a real- world environment, we developed and implemented three stabilization systems (see Fig. 2 in the main text): 
fully-automatic polarization stabilization, manual adjustment of photon arrival time, and manual adjustment of laser 
frequency. Note that automating the frequency and timing stabilization systems is straightforward, particularly if the 
active control elements are placed in Charlie's setup. 

The polarization stabilization system [311 I32j employed an additional laser (at Charlie's) and two polarization 
controllers (one at Alice's and one at Bob's). Every 10 s, Charlie disabled data collection for 0.5 s and sent high 
intensity, vertically polarized stabilization light to Alice and Bob. This light was detected by photodiodes at Alice's 
and Bob's, and used to trigger their commercially available polarization controllers (POCs), which were programmed 
to adjust the polarization of the stabilization light to vertical. This implies that Alice's and Bob's attenuated laser 
pulses, which were emitted horizontally polarized, both arrive horizontally polarized at Charlie's. 

To stabilize the frequency difference between Alice's and Bob's lasers, Alice used a frequency shifter (FS) that 
employed a linear phase chirp via a serrodyne modulation signal applied to a phase modulator. Whenever the error 
rate in the x-key increased significantly, Charlie communicated the frequency difference after measuring the beat 
frequency by mixing their unmodulated and unattenuated laser outputs on the beam splitter. Adjustments, in the 
worst case, were required every 30 minutes to maintain the difference below 10 MHz. 

To enable temporal synchronization, Charlie sent a master clock signal via a second set of fibers to Alice and 
Bob. Roughly every minute, Charlie measured the qubit arrival-time difference using his SPDs and high-resolution 
electronics and sent this information to Alice and Bob. They then adjusted their qubit generation times using function 
generators to apply a phase shift to the recovered master clock. This maintained the arrival-time difference under 
30 ps. 



DECOY-STATE ANALYSIS 

In MDI-QKD the secret key rate is given by 

S > Ql, (1 - /i2(efi)) - QlJh^iel,), (2) 

where h2{X) denotes the binary entropy function evaluated on X, and / describes the efficiency of error correction 
with respect to Shannon's noisy coding theorem. Furthermore, Qli-, ef^, Qucn ^ind e^^. are gains (Q - the probability 
of a projection onto \ip~) per emitted pair of pulses) and error rates (e - the ratio of erroneous to total projections 
onto \ip~)) in either the x- or z-basis for Alice and Bob sending single photons (denoted by subscript "11"), or for 
pulses emitted by Alice and Bob with mean photon number /i and a (denoted by subscript ^^iia^^ ) , respectively. While 
Q^^, and e^^ are directly accessible from experimental data, Qf^, efi have to be bounded using a decoy state method. 
We use a three-intensity decoy state method for the MDI-QKD protocol [231 that derives a lower bound for Qf^ 
and Qli and an upper bound for efi, to calculate a lower bound for the secure secret key rate. We denote the signal, 
decoy, and vacuum intensities by /i^, fid, and /i^, respectively, for Alice, and Bob (note that /it, = by definition). 
In our implementation Alice and Bob both select the same mean photon numbers for the three intensities and use 
channels of equal transmission. For compactness of notation, we omit the fj, when describing the gains and error 
rates (e.g. we write Q^^ to denote the gain in the z-basis when Alice and Bob both send photons using the signal 
intensity). Under these assumptions, the lower bound on Qf^ is given by 



Pl{^^s)Pl{^^d){PlMP2{^^s) - Pl{^^s)P2{^id)) 

where the various Pi{n) denote the probabihties that a pulse with Poissonian photon number distribution and mean 
/i contains exactly i photons, and QgifJ^d) and Q^{lJi-s) are given by 

Qg(M,) = P^{^Jid)Q:d + Po{f^d)Q^dv - PoM'q:., (4) 

QS(m,) = Poi^is)Q:s + Po{ps)Q:. - Poif^sfQ^,. (5) 

Similar equations are used to bound Qfi (we replace the superscript x by z). Finally, the error rate efi can then be 
computed as 

X ^ f^ddQdd - Po{^^d)e%dQ%d - -Po(Mrf)egt,Qrft, + Poif^d)'^<vQvv /RN 



where the upper bound holds if a lower bound is used for Qf^. Note that Qif, Qo'^il^-d), Qo'^(Ms) and e^i (Eqs. ^|6|) 
are uniquely determined through measurable gains and error rates. 

Our analysis in [28] determined that lowering fi^ as much as possible maximizes secret key rate. In these experiments, 
we select /i^ ~ 0.05 in order to obtain statistically significant data in a reasonable amount of time (see Suplementary 
Table |!l| 

SECURE KEY DISTRIBUTION USING MDI-QKD 

In this section we describe the assumptions underpinning secure key distribution in MDI-QKD as well as further 
technological and theoretical developments required for our current proof-of-principle demonstration to meet this goal. 
We note that any QKD system used to distribute secret key must be vetted against attacks arising from imperfections 
in its implementation [? ]. Protection against such attacks requires the development of hardware that strives to be 
as ideal as possible, in conjunction with the development of security proofs that are able to take into account those 
imperfections that inevitably remain in any realistic implementation. (Such proofs would bound the information 
leaked to an eavesdropper, which, in turn, allows removing it by means of privacy amplification) . Even for the heavily 
studied prepare-and-measure BB84 protocol, this is an area of ongoing research [34] , and more needs to be done for the 
new MDI-QKD protocol. Yet, MDI-QKD constitutes a very important development in this context as it eliminates all 
potential attack strategies related to imperfections in the measurement apparatus, including arbitrary measurement- 
basis misalignment errors as well as detector attacks that have recently been shown to provide the eavesdropper full 
information about the key without leaving a trace [Tmi4| . Remaining assumptions and required developments are: 

1. Quantum mechanics is correct and complete. This assumption is generally believed to be true. 

2. Alice's and Bob's laboratories are private. This assumption entails that no undesircd signals, e.g. RF 
electromagnetic radiation, escape from Alice's and Bob's apparatus when working in normal conditions. Infor- 
mation gain through such passive observation can be avoided using appropriate shielding, which, as is standard 
in academic QKD implementations, we have not spent any particular effort on. Furthermore, the assumption 
implies that Eve cannot actively obtain information about the experimental settings, e.g. by sending a probe, 
such as light, into the laboratories using the fiber that connects Alice or Bob, respectively, with the outside 
world, and analyzing the back reflection. This is often referred to as a Trojan horse attack [HIS]- And finally. Eve 
cannot actively influence Alice's or Bob's devices to modify their functioning. Protection against active attacks 
requires that the laboratories are isolated from signals sent by Eve, e.g. using optical isolators or attenuators. 
No such countermeasures were realized in our proof-of-principle demonstration. However, their implementation 
is straightforward, at least in what concerns attenuators and isolators [8]. We emphasize that there is no need 
to protect Charlie's laboratory; the MDI-QKD protocol ensures that it can even be run by the eavesdropper. 

3. Alice and Bob send phase-randomized attenuated pulses of light produced by a laser operated 
well above threshold. This ensures that the generated light pulses are correctly described by the density 



TABLE II. List of experimentally obtained error rates, e^^ , and gains, Q^'^ , used to calculate the secret key rate in four 
different configurations. For each configuration we show the mean photon numbers for the signal and decoy states, /is and 
fid, employed by Alice and Bob. The vacuum state corresponds to a mean photon number of /i^ ~ 0. We remind the reader 
that we omit the fi when writing the gains and error rates, writing only the subscript denoting the signal (s), decoy (d), or 
vacuum (v) state. We also indicate the lengths of fiber connecting Alice and Charlie {£a), Bob and Charlie {£b) and the total 
transmission loss (l). Finally, the computed secret key rate (S) is shown in bits per detector gate. Additionally, we measured 
g?;;^ = (7.1 ± 0.30) x I0"^° and e?;;'' = 0.49 ± 0.021, which is applied to all distances. 
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9.24(5) X 10"** 


eld 


0.48(3) 


Qvd 


8.59(9) X lO-' 


eld 


0.503(5) 



Fiber 


Spool 




Z-basis 








X-basis 






u 


30.98 km 


Qls 


1.67(1) X lO"'' 


els 


0.041(2) 


OL 


3.57(3) X 10"^ 


els 


0.274(3) 


Ib 


34.65 km 


Qlv 


6.7(2) X 10"' 


elv 


0.51(2) 


Qf. 


9.62(9) X 10-" 


eL 


0.498(4) 


Total loss / 


13.7 dB 


Qls 


4.4(2) X 10"' 


els 


0.48(2) 


Qls 


9.32(7) X 10-" 


^vs 


0.499(4) 


Ms 


0.279(6) 


Qdd 


6.0(1) X lO"' 


eld 


0.082(5) 


Qdd 


1.192(7) X 10"" 


e^d 


0.278(2) 


p-d 


0.050(1) 


Ql. 


4.7(4) X 10-« 


edv 


0.47(4) 


Qdv 


3.08(7) X 10"' 


edv 


0.50(1) 


S 


1.7(1.3) X 10-' 


Qld 


4.0(4) X 10-** 


eld 


0.41(4) 


Qld 


3.03(7) X 10-' 


eld 


0.50(1) 



Fiber 


Spool 




Z-basis 








X-basis 






iA 


40.80 km 


Qls 


5.57(6) X 10-" 


els 


0.053(2) 


Qls 


9.87(9) X 10"" 


els 


0.270(4) 


£b 


40.77 km 


Qlv 


2.15(9) X 10-' 


elv 


0.51(2) 


Qlv 


2.50(3) X 10-" 


'-sv 


0.505(7) 


Total loss / 


18.2 dB 


Qls 


1.88(8) X 10"' 


els 


0.49(2) 


Qls 


2.95(4) X 10"" 


els 


0.501(6) 


Us 


0.251(6) 


Qdd 


2.66(6) X 10-' 


edd 


0.129(8) 


Qld 


4.49(4) X 10" "" 


eld 


0.286(4) 


fJ-d 


0.050(1) 


Qdv 


2.8(2) X 10"** 


elv 


0.52(4) 


Qlv 


1.25(4) X 10"' 


elv 


0.51(1) 


S 


1.2(8) X 10"' 


Qld 


2.2(2) X 10-** 


evd 


0.45(4) 


Qld 


1.22(3) X 10"' 


evd 


0.51(1) 



Fiber 


Deployed 




Z-basis 








X-basis 






tA 


12.4 km 


Qls 


1.042(3) X 10-"* 


els 


0.0323(6) 


Qls 


2.020(8) X 10"'' 


els 


0.265(2) 


tB 


6.2 km 


Qlv 


2.96(6) X 10"" 


elv 


0.50(1) 


Qlv 


5.63(2) X 10"" 


elv 


0.492(2) 


Total loss / 


9.0 dB 


Qls 


1.87(4) X 10"" 


els 


0.52(1) 


Qls 


5.10(2) X 10"" 


eld 


0.512(2) 


[is 


0.402(2) 


Qld 


1.82(2) X 10"" 


eld 


0.071(3) 


Qld 


3.35(2) X 10"" 


eld 


0.269(3) 


f^d 


0.050(1) 


Qlv 


1.15(6) X 10"' 


edv 


0.53(3) 


Qlv 


8.5(1) X 10"' 


edv 


0.502(6) 


S 


1.5(5) X 10-" 


Qld 


8.4(5) X 10-« 


eld 


0.49(4) 


Qld 


8.5(1) X 10-' 


eld 


0.501(6) 



matrix p = J^n Pn{f^)\n){n\, where P„(^) 



is the Poisson distribution with mean photon number /i, and 



|n)(n| denotes the density matrix of an n-photon Fock state. This condition is easily met by generating every 
light pulse using a laser diode triggered by a short electrical pulse. However, as we carve qubits out of a laser 
beam with large coherence time using an intensity modulator, it is not fulfilled in our setup (more precisely, 
subsequent pulses are coherent). Yet, we point out that the solution to our problem is well understood and has 
been implemented before [3S] : it simply requires adding a phase modulator that randomizes the global phase of 
each qubit. 



4. The mean values of photons per pulse, as well as the encoded states are chosen randomly. No 

random choices have been implemented in our current proof-of-principle demonstration. Instead, we sent pulses 
with the same mean photon number and encoded the same qubit state during several minutes before changing 
the state or mean number. However, operating the phase and amplitude modulators that generate qubit states 
using adequate drivers connected to quantum random number generators is well understood [8], and meeting 
the requirement of random modulation is straightforward, though time consuming. 



Alice and Bob generate qubits in states that are sufficiently close to those that form two maximally 
conjugate bases. These states were denoted in the main text as |0), |1), |+) = -75(10) + |1)) and |— ) = 



4=(|0) — |1)), respectively. This assumption may currently not be satisfied (see [5S] for a detailed description 
of our experimental imperfections). For instance, considering states in different bases (for which the overlap 
should be 0.5), we find an average deviation of 0.074, and for different states in the same basis (for which we 
expect an overlap of zero), the average deviation is 0.013. According to the analyses in [MIES] these overlaps, 
together with the current detector performance, are insufficient to securely distribute key. However, we point 
out that both proofs lead to very conservative bounds. For instance, the proof in [M] requires a state generation 
procedure that artificially increases error rates and applies non-tight bounds, and hence underestimates secure 
key rates. We believe that future investigations will rapidly improve proof techniques and yield higher secret 
key rates (and result in secret key in cases in which current proofs predict no secret key). Furthermore, we 
note that straightforward technological improvements allow reducing the maximum deviation from the ideal 
overlap values to around 1 part in 1000. For instance, this can be accomplished by reducing ringing in our 
pulse generation by a factor of 5, and using commercially- available, state-of-the-art intensity modulators that 
allow suppressing the background by an additional 10-20 dB [37]. In addition, using state-of-the-art detectors 
with 93% quantum efficiency and IkHz noise [30] leads, according to simulation results with a theoretical model 
of MDI-QKD that we presented in [^S], to secret key rates similar to or above the ones reported in the main 
document, even using the conservative approach in |24j . 

6. Sufficiently weak correlations between qubit states and all degrees of freedom not used to encode 
the qubit. In principle, the various states generated by Alice and Bob could have differences in other degrees 
of freedom (i.e. polarization, spectral, spatial, or temporal modes), which could open a security loophole [3^ 
if not properly quantified and taken into account during privacy amplification. However, for MDI-QKD, the 
link between correlations with unobserved degrees of freedom and Eve's information gain is not yet clear. In 
particular, correlations are likely to degrade the visibility of the BSM, thus creating observable errors. The upper 
bound on Eve's information gain, possibly zero, can only be assessed using plausible arguments based on the 
actual implementation of the setup supplemented by careful measurements. For instance, in our implementation, 
the use of a single laser to generate all qubits states and of a single-mode fiber to transmit qubits from Alice, 
or Bob, to Charlie, respectively, makes it highly unlikely that correlation between states and photon spectra 
or spatial modes exist. Furthermore, careful programming of the function generator that generates all states 
through interaction with the same intensity modulator makes it very plausible that no temporal distinguishability 
is observable in our experiment. And finally, the polarization beam splitter at the exit of Alice's and Bob's 
laboratories ensures equal polarization of all time-bin qubit states. 

7. Appropriate classical post-processing of the sifted key, i.e. error correction and privacy amplifi- 
cation. Note that while we have not implemented error correction, we have used a realistic estimation of the 
error correction efficiency [B] to determine the potential secret key rate of our system. Furthermore, we did not 
consider finite key size effects in our proof-of-principle demonstration (in other words, we assumed that we could 
run our QKD devices during an infinitely long time and produce an infinite amount of measured data), which, 
in the case of MDI-QKD, have so far only been investigated using an overly conservative approach [39j . 

8. A short secret authentication key exists before starting QKD. This key is used to authenticate the 
classical communication channel during error correction and privacy amplification. As we did not implement 
any of these post-processing steps, we did not need any pre-established secret key. In an actual implementation, 
this step can, for instance, be accomplished during a personal meeting between Alice and Bob. 

We recall that some of the above topics are currently not as thoroughly studied for MDI-QKD as for prepare- 
and-measure QKD. However, the ability to close all side channels in measurement devices represents a significant 
step forward in closing the gap between theoretical security proofs and experimentally viable implementations. In 
particular, it has, for the first time, allowed for the development of security proofs in QKD that take arbitrary state 
generation and measurement errors into account, even though the efficiency of the current approaches can certainly 
be increased[? ]. In addition, for actual key distribution, our experimental implementation has to be improved along 
the lines discussed above. We leave these interesting and important topics for future investigations and emphasize 
that our work has focused on previously undemonstrated requirements for MDI-QKD, such as the Bell state 
measurement over deployed fiber, on improving the understanding of the capabilities and current limitations of our 
setup (including optimization and efficiency calculations of a decoy state analysis; for more information see ^28J) and 
on experimental demonstrations of the protocol over various distances as well as over deployed, real- world optical fiber. 



Let us briefly discuss the ideal case in which the quantum states encoded into attenuated laser pulses, as well as the 
projection measurements, are perfect. To gain some insight into how the difference in the error rates, e^^, arises[? ], 
we consider only the most likely case that can cause the detection pattern associated with a projection onto \iIj~) (this 
projection occurs if the two detectors indicate detections with 1.4±0.4 ns time difference). Specifically, we consider 
only the case in which two photons arrive at the beam splitter. Note that these photons can either come from the 
same person, or from different persons. 

• z-basis: Assuming that Alice and Bob both prepare states in the z-basis, only photons prepared in orthogonal 
states can cause a projection onto IV' )• This implies that one photon has to come from Alice, and the other 
one from Bob (if generated by the same person, both photons would be in the same state). Hence, taking into 
account Bob's bit flip, Alice and Bob always establish identical bits, i.e. e^^. (ideal) = 0. 

• x-basis: Assuming that both Alice and Bob prepare states in the x-basis, it is no longer true that only photons 
prepared in orthogonal states and by different persons can cause a projection onto IV" )■ Indeed, if the two 
photons have been prepared by the same person, it is possible to observe the detection pattern associated with 
a projection onto \'4'~)- In this case, given that all detected photons have been prepared by either one or the 
other person, the detection does not indicate any correlation between the states prepared by Alice and Bob. 
In turn, this leads to uncorrelated key bits. Thus, e^^ (ideal) is determined by the probability that one photon 
arrived from each person relative to the probability that two photons arrived from the same person. A detailed 
analysis for attenuated laser pulses with Poissonian photon number distribution, assuming an equal probability 
of photons arriving from either party, yields ejj^ (ideal) = 1/4. 
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